Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v99m-rxjx-rq75

Опубликовано: 10 дек. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 3.3

Описание

SAP Product Lifecycle Costing Client (versions below 4.7.1) application loads on demand a DLL that is available with Windows OS. This DLL is loaded from the computer running SAP Product Lifecycle Costing Client application. That particular DLL could be replaced by a malicious one, that could execute commands as being part of SAP Product Lifecycle Costing Client Application. On a successful attack, it can cause a low impact to confidentiality but no impact to the integrity and availability of the application.

SAP Product Lifecycle Costing Client (versions below 4.7.1) application loads on demand a DLL that is available with Windows OS. This DLL is loaded from the computer running SAP Product Lifecycle Costing Client application. That particular DLL could be replaced by a malicious one, that could execute commands as being part of SAP Product Lifecycle Costing Client Application. On a successful attack, it can cause a low impact to confidentiality but no impact to the integrity and availability of the application.

EPSS

Процентиль: 6%
0.00024
Низкий

3.3 Low

CVSS3

Дефекты

CWE-427

Связанные уязвимости

CVSS3: 3.3
nvd
около 1 года назад

SAP Product Lifecycle Costing Client (versions below 4.7.1) application loads on demand a DLL that is available with Windows OS. This DLL is loaded from the computer running SAP Product Lifecycle Costing Client application. That particular DLL could be replaced by a malicious one, that could execute commands as being part of SAP Product Lifecycle Costing Client Application. On a successful attack, it can cause a low impact to confidentiality but no impact to the integrity and availability of the application.

CVSS3: 3.3
fstec
около 1 года назад

Уязвимость программного обеспечения SAP Product Lifecycle Costing Client, связанная с неконтролируемым элементом пути поиска, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 6%
0.00024
Низкий

3.3 Low

CVSS3

Дефекты

CWE-427